I feel so dumb when I read kids doing these things. Back in High School all I knew was how I could run arbitrary executable files by renaming them to calc.exe. We also did the classic "take a screenshot of the desktop, set it as the wallpaper, then remove all icons and the start menu" thing.
Another good one on that level was using the Windows keyboard shortcut ctrl-alt-down to rotate the display upside down - totally harmless, but absolutely maddening if you don’t know how to undo it
IoT hacking and rickrolling my high school district
301–310 of 399 posts
Re: IoT hacking and rickrolling my high school district
#302Earlier quoted context omitted.
Not really. Sounds like this was class of '08, and at the time BackTrack would have been readily available and popular enough for a curious highschooler with a bit of computing background to find. As I recall etercap was built in and I wouldn't be at all surprised if there were tutorials for setting up scenarios almost exactly like what is described. Even the ARP balancing thing is the kind of too-clever-by-a-half so…
Maybe they hardcoded the real gateway's MAC Address.
Re: IoT hacking and rickrolling my high school district
#303Working in IT/tech for school district is the worst. My experience from many years ago - around 2002, I think: 1. First day on the job, email to boss: "Hey, the computer lab at Springfield High has a ton of known security flaws that are begging to be exploited." 2. Reply, 1 week later: "Sorry, we don't have any money for that. Just keep everything up-and-running." 3. 3 weeks later the computer lab at Springfield High…
> we don't have any money for that They always have the money. They just don't care about doing things properly. It simply isn't a priority for them. Makes me feel good when someone comes and exploits their negligence. It's like divine retribution and they're doing god's work. They tempt fate and the gods punish them by making them pay more than they would have paid had they done things right. Amazing.
Re: IoT hacking and rickrolling my high school district
#304Earlier quoted context omitted.
> All the computers displayed a popup window When I engaged in `net send` shenanigans at the local community college, at least the IT staff was smart enough to know where to scramble a runner whenever those dialog boxes popped up across campus. "ALL YOUR BASE ARE BELONG TO US" was quite the meme then, but apparently they thought it was some form of cyber-terrorism.
When I had my net send fun back in school, an IT guy found me and just explained that if it becomes a recurring thing, they'll have to disable it on the network. And that they would prefer to keep the functionality available, so it would be a real shame if I ruined that for them. I never did another one, because I understood it would be a dick move. No condescension, no threats. Just treating me like an adult with a…
Re: IoT hacking and rickrolling my high school district
#305Working in IT/tech for school district is the worst. My experience from many years ago - around 2002, I think: 1. First day on the job, email to boss: "Hey, the computer lab at Springfield High has a ton of known security flaws that are begging to be exploited." 2. Reply, 1 week later: "Sorry, we don't have any money for that. Just keep everything up-and-running." 3. 3 weeks later the computer lab at Springfield High…
I 'worked' for my own high school's IT dept, a few hours a week, as a student. It was an amazing experience working with those guys. I learned so many things, from how to punch, terminate, and run cables to how to set up a Ghost image and deploy it en masse across the district. One day one of the old macs was showing the frowny face in a in-session classroom. Boss sent me down there with specific instructions: "pull…
Heh. Nice.
A coworker's Mac wouldn't boot. I couldn't hear the hard drive. It was a model with the tip of the spindle exposed. I found a pencil with a gummy eraser. Gave the spindle a twist as I turned the power on.
Told the amazed user, "Do not turn off your computer until after you have backed up your data. That probably won't work twice."
Good times.
Re: IoT hacking and rickrolling my high school district
#306I thought I was cool being able to modify the ready message on printers across the school network. This is really impressive.
In middle school I used Javascript to change Google's button text from "I'm feeling lucky!" to "Andrew is the best!" (javascript:getElementById('').text='blah') I showed some other students who were so freaked out that I had "hacked Google" that I got the attention of the librarian, who promptly banned me from the library computers for the rest of the year, even after I refreshed the page to show them it wasn't "real…
Re: IoT hacking and rickrolling my high school district
#307We'd of course run out of stuff to do and start messing around with our newly honed skills. Learning about net send wasn't too bad, we just sent dumb messages to each other. But learning vbscript combined with net send... you could DoS the other machines with a for loop.
One morning I was playing around with the net send script, but accidentally plugged into the schoolwide LAN instead of our local network... every computer in the building got locked down with some idiotic message my 17 year old brain had come up with. IT took a educated guess and came down to our class and I fessed up, thankfully they let me off with a stern talking to and promises to never do it again.
Re: IoT hacking and rickrolling my high school district
#308Earlier quoted context omitted.
The school district itself was relatively chill, however the individual deans freaked out. Because the penetration report was sent to the tech team and not the deans, the deans were intent on finding out exactly who did the hack to find something to report to their bosses (and according to them concern about the grade book system being exposed?? Not sure how you’re supposed to rick roll a grade book but if anyone has…
>and according to them concern about the grade book system being exposed?? Junior year in high school, I got suspended for "hacking." The tl;dr is that I was using a proxy to fetch assignments for class (because the county decided "yeah, this state run Moodle instance is obviously not appropriate for education" and one of my classes used Moodle) and got caught with the proxy configuration screen open. I wish I was jo…
Re: IoT hacking and rickrolling my high school district
#309Re: IoT hacking and rickrolling my high school district
#310Three things are remarkable about this, and make it a happy story. First, that the pranksters were so egregiously responsible in the way they went about it. They avoided disrupting any actual educational activities; it was meant to be harmless fun, not vandalism. No harm came to anything here. Second, that they documented their findings to the administration as part of the action, including recommendations for improv…
The school district itself was relatively chill, however the individual deans freaked out. Because the penetration report was sent to the tech team and not the deans, the deans were intent on finding out exactly who did the hack to find something to report to their bosses (and according to them concern about the grade book system being exposed?? Not sure how you’re supposed to rick roll a grade book but if anyone has…
Assuming you took the video at the top of the article, it was presumably trivial to figure out who was in the class you were in and then rule out everyone who appears on camera as the camera man. Or just ask the teacher...